ืชื›ื•ื ื•ืช ื”ื”ื’ื“ืจื” ืฉืœ Palo Alto Networks: SSL VPN

ืชื›ื•ื ื•ืช ื”ื”ื’ื“ืจื” ืฉืœ Palo Alto Networks: SSL VPN

ืœืžืจื•ืช ื›ืœ ื”ื™ืชืจื•ื ื•ืช ืฉืœ ื—ื•ืžื•ืช ื”ืืฉ ืฉืœ Palo Alto Networks, ืื™ืŸ ื”ืจื‘ื” ื—ื•ืžืจ ื‘-RuNet ืขืœ ื”ื’ื“ืจืช ื”ืชืงื ื™ื ืืœื•, ื›ืžื• ื’ื ื˜ืงืกื˜ื™ื ื”ืžืชืืจื™ื ืืช ื—ื•ื•ื™ืช ื”ื™ื™ืฉื•ื ืฉืœื”ื. ื”ื—ืœื˜ื ื• ืœืกื›ื ืืช ื”ื—ื•ืžืจื™ื ืฉืฆื‘ืจื ื• ื‘ืžื”ืœืš ืขื‘ื•ื“ืชื ื• ืขื ื”ืฆื™ื•ื“ ืฉืœ ื”ืกืคืง ื”ื–ื” ื•ืœื“ื‘ืจ ืขืœ ื”ืชื›ื•ื ื•ืช ืฉื ืชืงืœื ื• ื‘ื”ืŸ ื‘ืžื”ืœืš ื‘ื™ืฆื•ืข ืคืจื•ื™ืงื˜ื™ื ืฉื•ื ื™ื.

ื›ื“ื™ ืœื”ื›ื™ืจ ืœื›ื ืืช Palo Alto Networks, ืžืืžืจ ื–ื” ื™ืกืชื›ืœ ืขืœ ื”ืชืฆื•ืจื” ื”ื ื“ืจืฉืช ืœืคืชืจื•ืŸ ืื—ืช ืžื‘ืขื™ื•ืช ื—ื•ืžืช ื”ืืฉ ื”ื ืคื•ืฆื•ืช ื‘ื™ื•ืชืจ - SSL VPN ืœื’ื™ืฉื” ืžืจื—ื•ืง. ื ื“ื‘ืจ ื’ื ืขืœ ืคื•ื ืงืฆื™ื•ืช ืฉื™ืจื•ืช ืœืชืฆื•ืจืช ื—ื•ืžืช ืืฉ ื›ืœืœื™ืช, ื–ื™ื”ื•ื™ ืžืฉืชืžืฉ, ื™ื™ืฉื•ืžื™ื ื•ืžื“ื™ื ื™ื•ืช ืื‘ื˜ื—ื”. ืื ื”ื ื•ืฉื ื™ืขื ื™ื™ืŸ ืืช ื”ืงื•ืจืื™ื, ื‘ืขืชื™ื“ ื ืฉื—ืจืจ ื—ื•ืžืจื™ื ื”ืžื ืชื—ื™ื VPN ืืชืจ ืœืืชืจ, ื ื™ืชื•ื‘ ื“ื™ื ืžื™ ื•ื ื™ื”ื•ืœ ืžืจื•ื›ื– ื‘ืืžืฆืขื•ืช ืคื ื•ืจืžื”.

ื—ื•ืžื•ืช ื”ืืฉ ืฉืœ Palo Alto Networks ืžืฉืชืžืฉื•ืช ื‘ืžืกืคืจ ื˜ื›ื ื•ืœื•ื’ื™ื•ืช ื—ื“ืฉื ื™ื•ืช, ื›ื•ืœืœ App-ID, User-ID, Content-ID. ื”ืฉื™ืžื•ืฉ ื‘ืคื•ื ืงืฆื™ื•ื ืœื™ื•ืช ื–ื• ืžืืคืฉืจ ืœืš ืœื”ื‘ื˜ื™ื— ืจืžืช ืื‘ื˜ื—ื” ื’ื‘ื•ื”ื”. ืœื“ื•ื’ืžื”, ืขื App-ID ื ื™ืชืŸ ืœื–ื”ื•ืช ืชืขื‘ื•ืจืช ืืคืœื™ืงืฆื™ื•ืช ืขืœ ืกืžืš ื—ืชื™ืžื•ืช, ืคืขื ื•ื— ื•ื”ื™ื•ืจื™ืกื˜ื™ืงื”, ืœืœื ืงืฉืจ ืœื™ืฆื™ืื” ื•ืœืคืจื•ื˜ื•ืงื•ืœ ื‘ืฉื™ืžื•ืฉ, ื›ื•ืœืœ ื‘ืชื•ืš ืžื ื”ืจืช SSL. User-ID ืžืืคืฉืจ ืœืš ืœื–ื”ื•ืช ืžืฉืชืžืฉื™ ืจืฉืช ื‘ืืžืฆืขื•ืช ืฉื™ืœื•ื‘ LDAP. Content-ID ืžืืคืฉืจ ืœืกืจื•ืง ืชืขื‘ื•ืจื” ื•ืœื–ื”ื•ืช ืงื‘ืฆื™ื ืžืฉื•ื“ืจื™ื ื•ืชื•ื›ื ื. ืคื•ื ืงืฆื™ื•ืช ื ื•ืกืคื•ืช ืฉืœ ื—ื•ืžืช ืืฉ ื›ื•ืœืœื•ืช ื”ื’ื ื” ืžืคื ื™ ื—ื“ื™ืจื”, ื”ื’ื ื” ืžืคื ื™ ืคื’ื™ืขื•ื™ื•ืช ื•ื”ืชืงืคื•ืช DoS, ืื ื˜ื™-ืจื™ื’ื•ืœ ืžื•ื‘ื ื”, ืกื™ื ื•ืŸ ื›ืชื•ื‘ื•ืช ืืชืจื™ื, ืืฉื›ื•ืœื•ืช ื•ื ื™ื”ื•ืœ ืžืจื•ื›ื–.

ืœืฆื•ืจืš ื”ื”ื“ื’ืžื” ื ืฉืชืžืฉ ื‘ืžืขืžื“ ืžื‘ื•ื“ื“, ื‘ืขืœ ืชืฆื•ืจื” ื–ื”ื” ืœืืžื™ืชื™ืช, ืœืžืขื˜ ืฉืžื•ืช ืžื›ืฉื™ืจื™ื, ืฉื ืชื—ื•ื AD ื•ื›ืชื•ื‘ื•ืช IP. ื‘ืžืฆื™ืื•ืช ื”ื›ืœ ื™ื•ืชืจ ืžืกื•ื‘ืš - ื™ื›ื•ืœื™ื ืœื”ื™ื•ืช ื”ืจื‘ื” ืกื ื™ืคื™ื. ื‘ืžืงืจื” ื–ื”, ื‘ืžืงื•ื ื—ื•ืžืช ืืฉ ื‘ื•ื“ื“ืช, ื™ื•ืชืงืŸ ืืฉื›ื•ืœ ื‘ื’ื‘ื•ืœื•ืช ื”ืืชืจื™ื ื”ืžืจื›ื–ื™ื™ื, ื•ื™ื™ืชื›ืŸ ืฉื™ื™ื“ืจืฉ ื’ื ื ื™ืชื•ื‘ ื“ื™ื ืžื™.

ืžืฉืžืฉ ืขืœ ื”ืžืขืžื“ PAN-OS 7.1.9. ื›ืชืฆื•ืจื” ื˜ื™ืคื•ืกื™ืช, ืฉืงื•ืœ ืจืฉืช ืขื ื—ื•ืžืช ืืฉ ืฉืœ Palo Alto Networks ื‘ืงืฆื”. ื—ื•ืžืช ื”ืืฉ ืžืกืคืงืช ื’ื™ืฉืช SSL VPN ืžืจื—ื•ืง ืœืžืฉืจื“ ื”ืจืืฉื™. ืชื—ื•ื ื”-Active Directory ื™ืฉืžืฉ ื›ืžืกื“ ื ืชื•ื ื™ื ืฉืœ ืžืฉืชืžืฉื™ื (ืื™ื•ืจ 1).

ืชื›ื•ื ื•ืช ื”ื”ื’ื“ืจื” ืฉืœ Palo Alto Networks: SSL VPN
ืื™ื•ืจ 1 - ื“ื™ืื’ืจืžืช ื‘ืœื•ืงื™ื ืฉืœ ืจืฉืช

ืฉืœื‘ื™ ื”ื’ื“ืจื”:

  1. ื”ื’ื“ืจื” ืžืจืืฉ ืฉืœ ื”ืžื›ืฉื™ืจ. ื”ื’ื“ืจืช ืฉื, ื›ืชื•ื‘ืช IP ืœื ื™ื”ื•ืœ, ืžืกืœื•ืœื™ื ืกื˜ื˜ื™ื™ื, ื—ืฉื‘ื•ื ื•ืช ืžื ื”ืœ, ืคืจื•ืคื™ืœื™ ื ื™ื”ื•ืœ
  2. ื”ืชืงื ืช ืจื™ืฉื™ื•ื ื•ืช, ื”ื’ื“ืจื” ื•ื”ืชืงื ืช ืขื“ื›ื•ื ื™ื
  3. ื”ื’ื“ืจืช ืื–ื•ืจื™ ืื‘ื˜ื—ื”, ืžืžืฉืงื™ ืจืฉืช, ืžื“ื™ื ื™ื•ืช ืชืขื‘ื•ืจื”, ืชืจื’ื•ื ื›ืชื•ื‘ื•ืช
  4. ื”ื’ื“ืจืช ืคืจื•ืคื™ืœ ืื™ืžื•ืช LDAP ื•ืชื›ื•ื ืช ื–ื™ื”ื•ื™ ืžืฉืชืžืฉ
  5. ื”ื’ื“ืจืช SSL VPN

1. ืžื•ื’ื“ืจ ืžืจืืฉ

ื”ื›ืœื™ ื”ืขื™ืงืจื™ ืœื”ื’ื“ืจืช ื—ื•ืžืช ื”ืืฉ ืฉืœ Palo Alto Networks ื”ื•ื ืžืžืฉืง ื”ืื™ื ื˜ืจื ื˜; ื ื™ื”ื•ืœ ื‘ืืžืฆืขื•ืช ื”-CLI ืืคืฉืจื™ ื’ื. ื›ื‘ืจื™ืจืช ืžื—ื“ืœ, ืžืžืฉืง ื”ื ื™ื”ื•ืœ ืžื•ื’ื“ืจ ืœื›ืชื•ื‘ืช IP 192.168.1.1/24, ื›ื ื™ืกื”: ืื“ืžื™ืŸ, ืกื™ืกืžื”: ืื“ืžื™ืŸ.

ืืชื” ื™ื›ื•ืœ ืœืฉื ื•ืช ืืช ื”ื›ืชื•ื‘ืช ืื• ืขืœ ื™ื“ื™ ื—ื™ื‘ื•ืจ ืœืžืžืฉืง ื”ืื™ื ื˜ืจื ื˜ ืžืื•ืชื” ืจืฉืช, ืื• ื‘ืืžืฆืขื•ืช ื”ืคืงื•ื“ื” ื”ื’ื“ืจ ืืช ื›ืชื•ื‘ืช ื”-ip ืฉืœ ืžืขืจื›ืช deviceconfig <> ืžืกื™ื›ืช ืจืฉืช <>. ื–ื” ืžื‘ื•ืฆืข ื‘ืžืฆื‘ ืชืฆื•ืจื”. ื›ื“ื™ ืœืขื‘ื•ืจ ืœืžืฆื‘ ืชืฆื•ืจื”, ื”ืฉืชืžืฉ ื‘ืคืงื•ื“ื” ืœื”ื’ื“ื™ืจ. ื›ืœ ื”ืฉื™ื ื•ื™ื™ื ื‘ื—ื•ืžืช ื”ืืฉ ืžืชืจื—ืฉื™ื ืจืง ืœืื—ืจ ืื™ืฉื•ืจ ื”ื”ื’ื“ืจื•ืช ืขืœ ื™ื“ื™ ื”ืคืงื•ื“ื” ืœื‘ืฆืข, ื”ืŸ ื‘ืžืฆื‘ ืฉื•ืจืช ื”ืคืงื•ื“ื” ื•ื”ืŸ ื‘ืžืžืฉืง ื”ืื™ื ื˜ืจื ื˜.

ื›ื“ื™ ืœืฉื ื•ืช ื”ื’ื“ืจื•ืช ื‘ืžืžืฉืง ื”ืื™ื ื˜ืจื ื˜, ื”ืฉืชืžืฉ ื‘ืกืขื™ืฃ ืžื›ืฉื™ืจ -> ื”ื’ื“ืจื•ืช ื›ืœืœื™ื•ืช ื•ื”ืชืงืŸ -> ื”ื’ื“ืจื•ืช ืžืžืฉืง ื ื™ื”ื•ืœ. ื ื™ืชืŸ ืœื”ื’ื“ื™ืจ ืืช ื”ืฉื, ื”ื‘ืื ืจื™ื, ืื–ื•ืจ ื”ื–ืžืŸ ื•ื”ื’ื“ืจื•ืช ืื—ืจื•ืช ื‘ื—ืœืง ื”ื”ื’ื“ืจื•ืช ื”ื›ืœืœื™ื•ืช (ืื™ื•ืจ 2).

ืชื›ื•ื ื•ืช ื”ื”ื’ื“ืจื” ืฉืœ Palo Alto Networks: SSL VPN
ืื™ื•ืจ 2 - ืคืจืžื˜ืจื™ื ืฉืœ ืžืžืฉืง ื ื™ื”ื•ืœ

ืื ืืชื” ืžืฉืชืžืฉ ื‘ื—ื•ืžืช ืืฉ ื•ื™ืจื˜ื•ืืœื™ืช ื‘ืกื‘ื™ื‘ืช ESXi, ื‘ืกืขื™ืฃ ื”ื’ื“ืจื•ืช ื›ืœืœื™ื•ืช ืขืœื™ืš ืœืืคืฉืจ ืืช ื”ืฉื™ืžื•ืฉ ื‘ื›ืชื•ื‘ืช ื”-MAC ืฉื”ื•ืงืฆืชื” ืขืœ ื™ื“ื™ ื”-Hypervisor, ืื• ืœื”ื’ื“ื™ืจ ืืช ื›ืชื•ื‘ื•ืช ื”-MAC ืฉืฆื•ื™ื ื• ื‘ืžืžืฉืงื™ ื—ื•ืžืช ื”ืืฉ ื‘-Hypervisor, ืื• ืœืฉื ื•ืช ืืช ื”ื”ื’ื“ืจื•ืช ืฉืœ ื”ืžืชื’ื™ื ื”ื•ื•ื™ืจื˜ื•ืืœื™ื™ื ื›ื“ื™ ืœืืคืฉืจ ืœ-MAC ืœืฉื ื•ืช ื›ืชื•ื‘ื•ืช. ืื—ืจืช, ื”ืชื ื•ืขื” ืœื ืชืขื‘ื•ืจ.

ืžืžืฉืง ื”ื ื™ื”ื•ืœ ืžื•ื’ื“ืจ ื‘ื ืคืจื“ ื•ืื™ื ื• ืžื•ืฆื’ ื‘ืจืฉื™ืžืช ืžืžืฉืงื™ ื”ืจืฉืช. ื‘ืคืจืง ื”ื’ื“ืจื•ืช ืžืžืฉืง ื ื™ื”ื•ืœ ืžืฆื™ื™ืŸ ืืช ืฉืขืจ ื‘ืจื™ืจืช ื”ืžื—ื“ืœ ืขื‘ื•ืจ ืžืžืฉืง ื”ื ื™ื”ื•ืœ. ืžืกืœื•ืœื™ื ืกื˜ื˜ื™ื™ื ืื—ืจื™ื ืžื•ื’ื“ืจื™ื ื‘ืกืขื™ืฃ ื”ื ืชื‘ื™ื ื”ื•ื•ื™ืจื˜ื•ืืœื™ื™ื; ืขืœ ื›ืš ื ื“ื•ืŸ ื‘ื”ืžืฉืš.

ื›ื“ื™ ืœืืคืฉืจ ื’ื™ืฉื” ืœืžื›ืฉื™ืจ ื“ืจืš ืžืžืฉืงื™ื ืื—ืจื™ื, ืขืœื™ืš ืœื™ืฆื•ืจ ืคืจื•ืคื™ืœ ื ื™ื”ื•ืœ ืคืจื•ืคื™ืœ ื ื™ื”ื•ืœ ืกืขื™ืฃ ืจืฉืช -> ืคืจื•ืคื™ืœื™ ืจืฉืช -> ืžืžืฉืง Mgmt ื•ืœื”ืงืฆื•ืช ืื•ืชื• ืœืžืžืฉืง ื”ืžืชืื™ื.

ืœืื—ืจ ืžื›ืŸ, ืขืœื™ืš ืœื”ื’ื“ื™ืจ DNS ื•-NTP ื‘ืงื˜ืข ืžื›ืฉื™ืจ -> ืฉื™ืจื•ืชื™ื ื›ื“ื™ ืœืงื‘ืœ ืขื“ื›ื•ื ื™ื ื•ืœื”ืฆื™ื’ ืืช ื”ืฉืขื” ื‘ืฆื•ืจื” ื ื›ื•ื ื” (ืื™ื•ืจ 3). ื›ื‘ืจื™ืจืช ืžื—ื“ืœ, ื›ืœ ื”ืชืขื‘ื•ืจื” ืฉื ื•ืฆืจืช ืขืœ ื™ื“ื™ ื—ื•ืžืช ื”ืืฉ ืžืฉืชืžืฉืช ื‘ื›ืชื•ื‘ืช ื”-IP ืฉืœ ืžืžืฉืง ื”ื ื™ื”ื•ืœ ื›ื›ืชื•ื‘ืช ื”-IP ื”ืžืงื•ืจ ืฉืœื”. ืืชื” ื™ื›ื•ืœ ืœื”ืงืฆื•ืช ืžืžืฉืง ืื—ืจ ืขื‘ื•ืจ ื›ืœ ืฉื™ืจื•ืช ืกืคืฆื™ืคื™ ื‘ืกืขื™ืฃ ืชืฆื•ืจืช ืžืกืœื•ืœ ืฉื™ืจื•ืช.

ืชื›ื•ื ื•ืช ื”ื”ื’ื“ืจื” ืฉืœ Palo Alto Networks: SSL VPN
ืื™ื•ืจ 3 - ืคืจืžื˜ืจื™ ืฉื™ืจื•ืช DNS, NTP ื•ืžืกืœื•ืœื™ ืžืขืจื›ืช

2. ื”ืชืงื ืช ืจื™ืฉื™ื•ื ื•ืช, ื”ื’ื“ืจื” ื•ื”ืชืงื ืช ืขื“ื›ื•ื ื™ื

ืœื”ืคืขืœื” ืžืœืื” ืฉืœ ื›ืœ ืคื•ื ืงืฆื™ื•ืช ื—ื•ืžืช ื”ืืฉ, ืขืœื™ืš ืœื”ืชืงื™ืŸ ืจื™ืฉื™ื•ืŸ. ืืชื” ื™ื›ื•ืœ ืœื”ืฉืชืžืฉ ื‘ืจื™ืฉื™ื•ืŸ ื ื™ืกื™ื•ืŸ ืขืœ ื™ื“ื™ ื‘ืงืฉืชื• ืžืฉื•ืชืคื™ Palo Alto Networks. ืชืงื•ืคืช ื”ืชื•ืงืฃ ืฉืœื• ื”ื™ื 30 ื™ื•ื. ื”ืจื™ืฉื™ื•ืŸ ืžื•ืคืขืœ ื‘ืืžืฆืขื•ืช ืงื•ื‘ืฅ ืื• ื‘ืืžืฆืขื•ืช Auth-Code. ืจื™ืฉื™ื•ื ื•ืช ืžื•ื’ื“ืจื™ื ื‘ืกืขื™ืฃ ืžื›ืฉื™ืจ -> ืจื™ืฉื™ื•ื ื•ืช (ื”ืื™ื•ืจ 4).
ืœืื—ืจ ื”ืชืงื ืช ื”ืจื™ืฉื™ื•ืŸ, ืขืœื™ืš ืœื”ื’ื“ื™ืจ ืืช ื”ืชืงื ืช ื”ืขื“ื›ื•ื ื™ื ื‘ืกืขื™ืฃ ืžื›ืฉื™ืจ -> ืขื“ื›ื•ื ื™ื ื“ื™ื ืžื™ื™ื.
ื‘ืกืขื™ืฃ ืžื›ืฉื™ืจ -> ืชื•ื›ื ื” ืืชื” ื™ื›ื•ืœ ืœื”ื•ืจื™ื“ ื•ืœื”ืชืงื™ืŸ ื’ืจืกืื•ืช ื—ื“ืฉื•ืช ืฉืœ PAN-OS.

ืชื›ื•ื ื•ืช ื”ื”ื’ื“ืจื” ืฉืœ Palo Alto Networks: SSL VPN
ืื™ื•ืจ 4 - ืœื•ื— ื‘ืงืจื” ืฉืœ ืจื™ืฉื™ื•ืŸ

3. ื”ื’ื“ืจืช ืื–ื•ืจื™ ืื‘ื˜ื—ื”, ืžืžืฉืงื™ ืจืฉืช, ืžื“ื™ื ื™ื•ืช ืชืขื‘ื•ืจื”, ืชืจื’ื•ื ื›ืชื•ื‘ื•ืช

ื—ื•ืžื•ืช ื”ืืฉ ืฉืœ Palo Alto Networks ืžืฉืชืžืฉื•ืช ื‘ืœื•ื’ื™ืงืช ืื–ื•ืจ ื‘ืขืช ื”ื’ื“ืจืช ื›ืœืœื™ ืจืฉืช. ืžืžืฉืงื™ ืจืฉืช ืžื•ืงืฆื™ื ืœืื–ื•ืจ ืžืกื•ื™ื, ื•ืื–ื•ืจ ื–ื” ืžืฉืžืฉ ื‘ื—ื•ืงื™ ืชื ื•ืขื”. ื’ื™ืฉื” ื–ื• ืžืืคืฉืจืช ื‘ืขืชื™ื“, ื‘ืขืช ืฉื™ื ื•ื™ ื”ื’ื“ืจื•ืช ื”ืžืžืฉืง, ืœื ืœืฉื ื•ืช ืืช ื›ืœืœื™ ื”ืชืขื‘ื•ืจื”, ืืœื ืœื”ืงืฆื•ืช ืžื—ื“ืฉ ืืช ื”ืžืžืฉืงื™ื ื”ื“ืจื•ืฉื™ื ืœืื–ื•ืจื™ื ื”ืžืชืื™ืžื™ื. ื›ื‘ืจื™ืจืช ืžื—ื“ืœ, ืชื ื•ืขื” ื‘ืชื•ืš ืื–ื•ืจ ืžื•ืชืจืช, ืชื ื•ืขื” ื‘ื™ืŸ ืื–ื•ืจื™ื ืืกื•ืจื”, ื›ืœืœื™ื ืžื•ื’ื“ืจื™ื ืžืจืืฉ ืื—ืจืื™ื ืœื›ืš ื‘ืจื™ืจืช ืžื—ื“ืœ ื‘ืชื•ืš ืื–ื•ืจ ะธ interzone-default.

ืชื›ื•ื ื•ืช ื”ื”ื’ื“ืจื” ืฉืœ Palo Alto Networks: SSL VPN
ืื™ื•ืจ 5 - ืื–ื•ืจื™ ื‘ื˜ื™ื—ื•ืช

ื‘ื“ื•ื’ืžื” ื–ื•, ืžืžืฉืง ื‘ืจืฉืช ื”ืคื ื™ืžื™ืช ืžื•ืงืฆื” ืœืื–ื•ืจ ืคื ื™ืžื™, ื•ื”ืžืžืฉืง ื”ืคื•ื ื” ืœืื™ื ื˜ืจื ื˜ ืžื•ืงืฆื” ืœืื–ื•ืจ ื—ื™ืฆื•ื ื™. ืขื‘ื•ืจ SSL VPN, ืžืžืฉืง ืžื ื”ืจื” ื ื•ืฆืจ ื•ื”ื•ืงืฆื” ืœืื–ื•ืจ VPN (ื”ืื™ื•ืจ 5).

ืžืžืฉืงื™ ืจืฉืช ื—ื•ืžืช ื”ืืฉ ืฉืœ Palo Alto Networks ื™ื›ื•ืœื™ื ืœืคืขื•ืœ ื‘ื—ืžื™ืฉื” ืžืฆื‘ื™ื ืฉื•ื ื™ื:

  • ื‘ืจื– - ืžืฉืžืฉ ืœืื™ืกื•ืฃ ืชืขื‘ื•ืจื” ืœืžื˜ืจื•ืช ื ื™ื˜ื•ืจ ื•ื ื™ืชื•ื—
  • HA - ืžืฉืžืฉ ืœื”ืคืขืœืช ืืฉื›ื•ืœ
  • ื—ื•ื˜ ื•ื™ืจื˜ื•ืืœื™ - ื‘ืžืฆื‘ ื–ื”, Palo Alto Networks ืžืฉืœื‘ืช ืฉื ื™ ืžืžืฉืงื™ื ื•ืžืขื‘ื™ืจื” ืชื ื•ืขื” ื‘ื™ื ื™ื”ื ื‘ืฉืงื™ืคื•ืช ืžื‘ืœื™ ืœืฉื ื•ืช ื›ืชื•ื‘ื•ืช MAC ื•-IP
  • ืฉื›ื‘ื” 2 - ืœื”ื—ืœื™ืฃ ืžืฆื‘
  • ืฉื›ื‘ื” 3 - ืžืฆื‘ ื ืชื‘

ืชื›ื•ื ื•ืช ื”ื”ื’ื“ืจื” ืฉืœ Palo Alto Networks: SSL VPN
ืื™ื•ืจ 6 - ื”ื’ื“ืจืช ืžืฆื‘ ื”ื”ืคืขืœื” ืฉืœ ื”ืžืžืฉืง

ื‘ื“ื•ื’ืžื” ื–ื•, ื™ืฉืžืฉ ืžืฆื‘ Layer3 (ืื™ื•ืจ 6). ืคืจืžื˜ืจื™ ืžืžืฉืง ื”ืจืฉืช ืžืฆื™ื™ื ื™ื ืืช ื›ืชื•ื‘ืช ื”-IP, ืžืฆื‘ ื”ื”ืคืขืœื” ื•ืืช ืื–ื•ืจ ื”ืื‘ื˜ื—ื” ื”ืžืชืื™ื. ื‘ื ื•ืกืฃ ืœืžืฆื‘ ื”ื”ืคืขืœื” ืฉืœ ื”ืžืžืฉืง, ืขืœื™ืš ืœื”ืงืฆื•ืช ืื•ืชื• ืœื ืชื‘ ื”ื•ื™ืจื˜ื•ืืœื™ ืฉืœ ื ืชื‘ Virtual Router, ื–ื”ื• ืื ืœื•ื’ื™ ืฉืœ ืžื•ืคืข VRF ื‘-Palo Alto Networks. ื ืชื‘ื™ื ื•ื™ืจื˜ื•ืืœื™ื™ื ืžื‘ื•ื“ื“ื™ื ื–ื” ืžื–ื” ื•ื™ืฉ ืœื”ื ื˜ื‘ืœืื•ืช ื ื™ืชื•ื‘ ื•ื”ื’ื“ืจื•ืช ืคืจื•ื˜ื•ืงื•ืœ ืจืฉืช ืžืฉืœื”ื.

ื”ื’ื“ืจื•ืช ื”ื ืชื‘ ื”ื•ื•ื™ืจื˜ื•ืืœื™ ืžืฆื™ื™ื ื•ืช ืžืกืœื•ืœื™ื ืกื˜ื˜ื™ื™ื ื•ื”ื’ื“ืจื•ืช ืคืจื•ื˜ื•ืงื•ืœ ื ื™ืชื•ื‘. ื‘ื“ื•ื’ืžื” ื–ื•, ื ื•ืฆืจ ืจืง ืžืกืœื•ืœ ื‘ืจื™ืจืช ืžื—ื“ืœ ืœื’ื™ืฉื” ืœืจืฉืชื•ืช ื—ื™ืฆื•ื ื™ื•ืช (ืื™ื•ืจ 7).

ืชื›ื•ื ื•ืช ื”ื”ื’ื“ืจื” ืฉืœ Palo Alto Networks: SSL VPN
ืื™ื•ืจ 7 - ื”ื’ื“ืจืช ื ืชื‘ ื•ื™ืจื˜ื•ืืœื™

ืฉืœื‘ ื”ืชืฆื•ืจื” ื”ื‘ื ื”ื•ื ืžื“ื™ื ื™ื•ืช ืชื ื•ืขื”, ืกืขื™ืฃ ืžื“ื™ื ื™ื•ืช -> ืื‘ื˜ื—ื”. ื“ื•ื’ืžื” ืœืชืฆื•ืจื” ืžื•ืฆื’ืช ื‘ืื™ื•ืจ 8. ื”ื”ื™ื’ื™ื•ืŸ ืฉืœ ื”ื›ืœืœื™ื ื–ื”ื” ืœื›ืœ ื—ื•ืžื•ืช ื”ืืฉ. ื”ื—ื•ืงื™ื ื ื‘ื“ืงื™ื ืžืœืžืขืœื” ืœืžื˜ื”, ืขื“ ืœื”ืชืืžื” ื”ืจืืฉื•ื ื”. ืชื™ืื•ืจ ืงืฆืจ ืฉืœ ื”ื›ืœืœื™ื:

1. ื’ื™ืฉื” ืœ-SSL VPN ืœืคื•ืจื˜ืœ ื”ืื™ื ื˜ืจื ื˜. ืžืืคืฉืจ ื’ื™ืฉื” ืœืคื•ืจื˜ืœ ื”ืื™ื ื˜ืจื ื˜ ื›ื“ื™ ืœืืžืช ื—ื™ื‘ื•ืจื™ื ืžืจื•ื—ืงื™ื
2. ืชืขื‘ื•ืจืช VPN โ€“ ืžืืคืฉืจืช ืชืขื‘ื•ืจื” ื‘ื™ืŸ ื—ื™ื‘ื•ืจื™ื ืžืจื•ื—ืงื™ื ืœืžืฉืจื“ ื”ืจืืฉื™
3. ืื™ื ื˜ืจื ื˜ ื‘ืกื™ืกื™ โ€“ ืžืืคืฉืจ ืืคืœื™ืงืฆื™ื•ืช dns, ping, traceroute, ntp. ื—ื•ืžืช ื”ืืฉ ืžืืคืฉืจืช ื™ื™ืฉื•ืžื™ื ื”ืžื‘ื•ืกืกื™ื ืขืœ ื—ืชื™ืžื•ืช, ืคืขื ื•ื— ื•ื”ื™ื•ืจื™ืกื˜ื™ืงื” ื•ืœื ืขืœ ืžืกืคืจื™ ื™ืฆื™ืื•ืช ื•ืคืจื•ื˜ื•ืงื•ืœื™ื, ื•ื–ื• ื”ืกื™ื‘ื” ืฉื‘ืกืขื™ืฃ ื”ืฉื™ืจื•ืช ื›ืชื•ื‘ ื‘ืจื™ืจืช ืžื—ื“ืœ ืฉืœ ื™ื™ืฉื•ื. ื™ืฆื™ืืช/ืคืจื•ื˜ื•ืงื•ืœ ื‘ืจื™ืจืช ืžื—ื“ืœ ืขื‘ื•ืจ ื™ื™ืฉื•ื ื–ื”
4. ื’ื™ืฉื” ืœืื™ื ื˜ืจื ื˜ โ€“ ืžืืคืฉืจ ื’ื™ืฉื” ืœืื™ื ื˜ืจื ื˜ ื‘ืืžืฆืขื•ืช ืคืจื•ื˜ื•ืงื•ืœื™ HTTP ื•-HTTPS ืœืœื ืฉืœื™ื˜ื” ื‘ืืคืœื™ืงืฆื™ื”
5,6. ื›ืœืœื™ ื‘ืจื™ืจืช ืžื—ื“ืœ ืขื‘ื•ืจ ืชืขื‘ื•ืจื” ืื—ืจืช.

ืชื›ื•ื ื•ืช ื”ื”ื’ื“ืจื” ืฉืœ Palo Alto Networks: SSL VPN
ืื™ื•ืจ 8 - ื“ื•ื’ืžื” ืœื”ื’ื“ืจืช ื›ืœืœื™ ืจืฉืช

ื›ื“ื™ ืœื”ื’ื“ื™ืจ NAT, ื”ืฉืชืžืฉ ื‘ืกืขื™ืฃ ืžื“ื™ื ื™ื•ืช -> NAT. ื“ื•ื’ืžื” ืœืชืฆื•ืจืช NAT ืžื•ืฆื’ืช ื‘ืื™ื•ืจ 9.

ืชื›ื•ื ื•ืช ื”ื”ื’ื“ืจื” ืฉืœ Palo Alto Networks: SSL VPN
ืื™ื•ืจ 9 - ื“ื•ื’ืžื” ืœืชืฆื•ืจืช NAT

ืขื‘ื•ืจ ื›ืœ ืชืขื‘ื•ืจื” ืคื ื™ืžื™ืช ืœื—ื™ืฆื•ื ื™ืช, ื ื™ืชืŸ ืœืฉื ื•ืช ืืช ื›ืชื•ื‘ืช ื”ืžืงื•ืจ ืœื›ืชื•ื‘ืช ื”-IP ื”ื—ื™ืฆื•ื ื™ืช ืฉืœ ื—ื•ืžืช ื”ืืฉ ื•ืœื”ืฉืชืžืฉ ื‘ื›ืชื•ื‘ืช ื™ืฆื™ืื” ื“ื™ื ืžื™ืช (PAT).

4. ื”ื’ื“ืจืช ืคืจื•ืคื™ืœ ืื™ืžื•ืช LDAP ื•ืคื•ื ืงืฆื™ื™ืช ื–ื™ื”ื•ื™ ืžืฉืชืžืฉ
ืœืคื ื™ ื—ื™ื‘ื•ืจ ืžืฉืชืžืฉื™ื ื‘ืืžืฆืขื•ืช SSL-VPN, ืขืœื™ืš ืœื”ื’ื“ื™ืจ ืžื ื’ื ื•ืŸ ืื™ืžื•ืช. ื‘ื“ื•ื’ืžื” ื–ื•, ื”ืื™ืžื•ืช ื™ืชืจื—ืฉ ืœื‘ืงืจ ื”ืชื—ื•ื ืฉืœ Active Directory ื“ืจืš ืžืžืฉืง ื”ืื™ื ื˜ืจื ื˜ ืฉืœ Palo Alto Networks.

ืชื›ื•ื ื•ืช ื”ื”ื’ื“ืจื” ืฉืœ Palo Alto Networks: SSL VPN
ืื™ื•ืจ 10 - ืคืจื•ืคื™ืœ LDAP

ื›ื“ื™ ืฉื”ืื™ืžื•ืช ื™ืขื‘ื•ื“, ืขืœื™ืš ืœื”ื’ื“ื™ืจ ืคืจื•ืคื™ืœ LDAP ะธ ืคืจื•ืคื™ืœ ืื™ืžื•ืช. ื‘ืงื˜ืข ืžื›ืฉื™ืจ -> ืคืจื•ืคื™ืœื™ ืฉืจืช -> LDAP (ืื™ื•ืจ 10) ืขืœื™ืš ืœืฆื™ื™ืŸ ืืช ื›ืชื•ื‘ืช ื”-IP ื•ื”ื™ืฆื™ืื” ืฉืœ ื‘ืงืจ ื”ืชื—ื•ื, ืกื•ื’ LDAP ื•ื—ืฉื‘ื•ืŸ ื”ืžืฉืชืžืฉ ื”ื›ืœื•ืœื™ื ื‘ืงื‘ื•ืฆื•ืช ืžืคืขื™ืœื™ ืฉืจืชื™ื, ืงื•ืจืื™ ื™ื•ืžืŸ ืื™ืจื•ืขื™ื, ืžืฉืชืžืฉื™ COM ืžื‘ื•ื–ืจื™ื. ื•ืื– ื‘ืงื˜ืข ืžื›ืฉื™ืจ -> ืคืจื•ืคื™ืœ ืื™ืžื•ืช ืฆื•ืจ ืคืจื•ืคื™ืœ ืื™ืžื•ืช (ืื™ื•ืจ 11), ืกืžืŸ ืืช ื”ืคืจื•ืคื™ืœ ืฉื ื•ืฆืจ ืงื•ื“ื ืœื›ืŸ ืคืจื•ืคื™ืœ LDAP ื•ื‘ื›ืจื˜ื™ืกื™ื™ื” ืžืชืงื“ื ืื ื• ืžืฆื™ื™ื ื™ื ืืช ืงื‘ื•ืฆืช ื”ืžืฉืชืžืฉื™ื (ืื™ื•ืจ 12) ื”ืžื•ืจืฉื™ืช ื’ื™ืฉื” ืžืจื—ื•ืง. ื—ืฉื•ื‘ ืœืฆื™ื™ืŸ ืืช ื”ืคืจืžื˜ืจ ื‘ืคืจื•ืคื™ืœ ืฉืœื›ื ื“ื•ืžื™ื™ืŸ ืžืฉืชืžืฉ, ืื—ืจืช ื”ืจืฉืื” ืžื‘ื•ืกืกืช ืงื‘ื•ืฆื” ืœื ืชืขื‘ื•ื“. ื”ืฉื“ื” ื—ื™ื™ื‘ ืœืฆื™ื™ืŸ ืืช ืฉื ื”ื“ื•ืžื™ื™ืŸ ืฉืœ NetBIOS.

ืชื›ื•ื ื•ืช ื”ื”ื’ื“ืจื” ืฉืœ Palo Alto Networks: SSL VPN
ืื™ื•ืจ 11 - ืคืจื•ืคื™ืœ ืื™ืžื•ืช

ืชื›ื•ื ื•ืช ื”ื”ื’ื“ืจื” ืฉืœ Palo Alto Networks: SSL VPN
ืื™ื•ืจ 12 - ื‘ื—ื™ืจืช ืงื‘ื•ืฆืช AD

ื”ืฉืœื‘ ื”ื‘ื ื”ื•ื ื”ื”ืชืงื ื” ืžื›ืฉื™ืจ -> ื–ื™ื”ื•ื™ ืžืฉืชืžืฉ. ื›ืืŸ ืขืœื™ืš ืœืฆื™ื™ืŸ ืืช ื›ืชื•ื‘ืช ื”-IP ืฉืœ ื‘ืงืจ ื”ืชื—ื•ื, ืื™ืฉื•ืจื™ ื—ื™ื‘ื•ืจ ื•ื’ื ืœื”ื’ื“ื™ืจ ื”ื’ื“ืจื•ืช ื”ืคืขืœ ื™ื•ืžืŸ ืื‘ื˜ื—ื”, ืืคืฉืจ ื”ืคืขืœื”, ืืคืฉืจ ื‘ื“ื™ืงื” (ืื™ื•ืจ 13). ื‘ืคืจืง ืžื™ืคื•ื™ ืงื‘ื•ืฆืชื™ (ืื™ื•ืจ 14) ืขืœื™ืš ืœืฆื™ื™ืŸ ืืช ื”ืคืจืžื˜ืจื™ื ืœื–ื™ื”ื•ื™ ืื•ื‘ื™ื™ืงื˜ื™ื ื‘-LDAP ื•ืืช ืจืฉื™ืžืช ื”ืงื‘ื•ืฆื•ืช ืฉื™ืฉืžืฉื• ืœื”ืจืฉืื”. ื‘ื“ื™ื•ืง ื›ืžื• ื‘ืคืจื•ืคื™ืœ ื”ืื™ืžื•ืช, ื›ืืŸ ืืชื” ืฆืจื™ืš ืœื”ื’ื“ื™ืจ ืืช ื”ืคืจืžื˜ืจ User Domain.

ืชื›ื•ื ื•ืช ื”ื”ื’ื“ืจื” ืฉืœ Palo Alto Networks: SSL VPN
ืื™ื•ืจ 13 - ืคืจืžื˜ืจื™ื ืฉืœ ืžื™ืคื•ื™ ืžืฉืชืžืฉ

ืชื›ื•ื ื•ืช ื”ื”ื’ื“ืจื” ืฉืœ Palo Alto Networks: SSL VPN
ืื™ื•ืจ 14 - ืคืจืžื˜ืจื™ื ืฉืœ ืžื™ืคื•ื™ ืงื‘ื•ืฆื•ืช

ื”ืฉืœื‘ ื”ืื—ืจื•ืŸ ื‘ืฉืœื‘ ื–ื” ื”ื•ื ื™ืฆื™ืจืช ืื–ื•ืจ VPN ื•ืžืžืฉืง ืขื‘ื•ืจ ืื•ืชื• ืื–ื•ืจ. ืขืœื™ืš ืœื”ืคืขื™ืœ ืืช ื”ืืคืฉืจื•ืช ื‘ืžืžืฉืง ืืคืฉืจ ื–ื™ื”ื•ื™ ืžืฉืชืžืฉ (ื”ืื™ื•ืจ 15).

ืชื›ื•ื ื•ืช ื”ื”ื’ื“ืจื” ืฉืœ Palo Alto Networks: SSL VPN
ืื™ื•ืจ 15 - ื”ื’ื“ืจืช ืื–ื•ืจ VPN

5. ื”ื’ื“ืจืช SSL VPN

ืœืคื ื™ ื—ื™ื‘ื•ืจ ืœ-SSL VPN, ื”ืžืฉืชืžืฉ ื”ืžืจื•ื—ืง ื—ื™ื™ื‘ ืœืขื‘ื•ืจ ืœืคื•ืจื˜ืœ ื”ืื™ื ื˜ืจื ื˜, ืœืืžืช ื•ืœื”ื•ืจื™ื“ ืืช ืœืงื•ื— Global Protect. ืœืื—ืจ ืžื›ืŸ, ืœืงื•ื— ื–ื” ื™ื‘ืงืฉ ืื™ืฉื•ืจื™ื ื•ื™ืชื—ื‘ืจ ืœืจืฉืช ื”ืืจื’ื•ื ื™ืช. ืคื•ืจื˜ืœ ื”ืื™ื ื˜ืจื ื˜ ืคื•ืขืœ ื‘ืžืฆื‘ https ื•ื‘ื”ืชืื ืœื›ืš ื™ืฉ ืœื”ืชืงื™ืŸ ืขื‘ื•ืจื• ืื™ืฉื•ืจ. ื”ืฉืชืžืฉ ื‘ืื™ืฉื•ืจ ืฆื™ื‘ื•ืจื™ ื‘ืžื™ื“ืช ื”ืืคืฉืจ. ืื– ื”ืžืฉืชืžืฉ ืœื ื™ืงื‘ืœ ืื–ื”ืจื” ืขืœ ืื™ ืชืงืคื•ืช ื”ืชืขื•ื“ื” ื‘ืืชืจ. ืื ืœื ื ื™ืชืŸ ืœื”ืฉืชืžืฉ ื‘ืชืขื•ื“ื” ืฆื™ื‘ื•ืจื™ืช, ืขืœื™ืš ืœื”ื ืคื™ืง ืชืขื•ื“ื” ืžืฉืœืš, ืฉืชืฉืžืฉ ื‘ื“ืฃ ื”ืื™ื ื˜ืจื ื˜ ืขื‘ื•ืจ https. ื–ื” ื™ื›ื•ืœ ืœื”ื™ื•ืช ื—ืชื•ื ืขืฆืžื™ ืื• ืœื”ื ืคื™ืง ื“ืจืš ืจืฉื•ืช ืื™ืฉื•ืจื™ื ืžืงื•ืžื™ืช. ื”ืžื—ืฉื‘ ื”ืžืจื•ื—ืง ื—ื™ื™ื‘ ืœื”ื™ื•ืช ื‘ืขืœ ืื™ืฉื•ืจ ืฉื•ืจืฉ ืื• ื—ืชื™ืžื” ืขืฆืžื™ืช ื‘ืจืฉื™ืžืช ืจืฉื•ื™ื•ืช ื”ืฉื•ืจืฉ ื”ืžื”ื™ืžื ื•ืช ื›ื“ื™ ืฉื”ืžืฉืชืžืฉ ืœื ื™ืงื‘ืœ ืฉื’ื™ืื” ื‘ืขืช ื—ื™ื‘ื•ืจ ืœืคื•ืจื˜ืœ ื”ืื™ื ื˜ืจื ื˜. ื“ื•ื’ืžื” ื–ื• ืชืฉืชืžืฉ ื‘ืื™ืฉื•ืจ ืฉื”ื•ื ืคืง ื‘ืืžืฆืขื•ืช Active Directory Certificate Services.

ื›ื“ื™ ืœื”ื ืคื™ืง ืื™ืฉื•ืจ, ืขืœื™ืš ืœื™ืฆื•ืจ ื‘ืงืฉืช ืื™ืฉื•ืจ ื‘ืžื“ื•ืจ ืžื›ืฉื™ืจ -> ื ื™ื”ื•ืœ ืื™ืฉื•ืจื™ื -> ืื™ืฉื•ืจื™ื -> ืฆื•ืจ. ื‘ื‘ืงืฉื” ืื ื• ืžืฆื™ื™ื ื™ื ืืช ืฉื ื”ืชืขื•ื“ื” ื•ืืช ื›ืชื•ื‘ืช ื”-IP ืื• ื”-FQDN ืฉืœ ืคื•ืจื˜ืœ ื”ืื™ื ื˜ืจื ื˜ (ืื™ื•ืจ 16). ืœืื—ืจ ื™ืฆื™ืจืช ื”ื‘ืงืฉื”, ื”ื•ืจื“ โ€Ž.csr ืงื•ื‘ืฅ ื•ื”ืขืชืง ืืช ืชื•ื›ื ื• ืœืฉื“ื” ื‘ืงืฉืช ื”ืื™ืฉื•ืจ ื‘ื˜ื•ืคืก ื”ืื™ื ื˜ืจื ื˜ AD CS Web Enrollment. ื‘ื”ืชืื ืœืื•ืคืŸ ืฉื‘ื• ืžื•ื’ื“ืจืช ืจืฉื•ืช ื”ืื™ืฉื•ืจื™ื, ื™ืฉ ืœืืฉืจ ืืช ื‘ืงืฉืช ื”ืื™ืฉื•ืจ ื•ืœื”ื•ืจื™ื“ ืืช ื”ืื™ืฉื•ืจ ืฉื”ื•ื ืคืง ื‘ืคื•ืจืžื˜ ืื™ืฉื•ืจ ืžืงื•ื“ื“ Base64. ื‘ื ื•ืกืฃ, ืขืœื™ืš ืœื”ื•ืจื™ื“ ืืช ืื™ืฉื•ืจ ื”ื‘ืกื™ืก ืฉืœ ืจืฉื•ืช ื”ืื™ืฉื•ืจื™ื. ืœืื—ืจ ืžื›ืŸ ืขืœื™ืš ืœื™ื™ื‘ื ืืช ืฉื ื™ ื”ืื™ืฉื•ืจื™ื ืœืชื•ืš ื—ื•ืžืช ื”ืืฉ. ื‘ืขืช ื™ื™ื‘ื•ื โ€‹โ€‹ืื™ืฉื•ืจ ืœืคื•ืจื˜ืœ ืื™ื ื˜ืจื ื˜, ืขืœื™ืš ืœื‘ื—ื•ืจ ืืช ื”ื‘ืงืฉื” ื‘ืกื˜ื˜ื•ืก ื”ืžืžืชื™ื ื” ื•ืœืœื—ื•ืฅ ืขืœ ื™ื™ื‘ื•ื. ืฉื ื”ืชืขื•ื“ื” ื—ื™ื™ื‘ ืœื”ืชืื™ื ืœืฉื ืฉืฆื•ื™ืŸ ืงื•ื“ื ืœื›ืŸ ื‘ื‘ืงืฉื”. ื ื™ืชืŸ ืœืฆื™ื™ืŸ ืืช ื”ืฉื ืฉืœ ืชืขื•ื“ืช ื”ืฉื•ืจืฉ ื‘ืื•ืคืŸ ืฉืจื™ืจื•ืชื™. ืœืื—ืจ ื™ื™ื‘ื•ื โ€‹โ€‹ื”ืื™ืฉื•ืจ, ืขืœื™ืš ืœื™ืฆื•ืจ ืคืจื•ืคื™ืœ ืฉื™ืจื•ืช SSL/TLS ืกืขื™ืฃ ืžื›ืฉื™ืจ -> ื ื™ื”ื•ืœ ืื™ืฉื•ืจื™ื. ื‘ืคืจื•ืคื™ืœ ืื ื• ืžืฆื™ื™ื ื™ื ืืช ื”ืชืขื•ื“ื” ืฉื™ื•ื‘ืื” ื‘ืขื‘ืจ.

ืชื›ื•ื ื•ืช ื”ื”ื’ื“ืจื” ืฉืœ Palo Alto Networks: SSL VPN
ืื™ื•ืจ 16 โ€“ ื‘ืงืฉืช ืชืขื•ื“ื”

ื”ืฉืœื‘ ื”ื‘ื ื”ื•ื ื”ื’ื“ืจืช ืื•ื‘ื™ื™ืงื˜ื™ื Global Protect Gateway ะธ ืคื•ืจื˜ืœ ืคืจื•ื˜ืงื˜ ื”ืขื•ืœืžื™ ืกืขื™ืฃ ืจืฉืช -> Global Protect. ื‘ื”ื’ื“ืจื•ืช Global Protect Gateway ืฆื™ื™ืŸ ืืช ื›ืชื•ื‘ืช ื”-IP ื”ื—ื™ืฆื•ื ื™ืช ืฉืœ ื—ื•ืžืช ื”ืืฉ, ื›ืžื• ื’ื ืฉื ื•ืฆืจื” ื‘ืขื‘ืจ ืคืจื•ืคื™ืœ SSL, ืคืจื•ืคื™ืœ ืื™ืžื•ืช, ืžืžืฉืง ืžื ื”ืจื” ื•ื”ื’ื“ืจื•ืช IP ืฉืœ ื”ืœืงื•ื—. ืขืœื™ืš ืœืฆื™ื™ืŸ ืžืื’ืจ ืฉืœ ื›ืชื•ื‘ื•ืช IP ืฉืžื”ืŸ ืชื•ืงืฆื” ื”ื›ืชื•ื‘ืช ืœืœืงื•ื—, ื•-Access Route - ืืœื• ืจืฉืชื•ืช ื”ืžืฉื ื” ืืœื™ื”ืŸ ื™ื”ื™ื” ืœืœืงื•ื— ืžืกืœื•ืœ. ืื ื”ืžืฉื™ืžื” ื”ื™ื ืœืขื˜ื•ืฃ ืืช ื›ืœ ืชืขื‘ื•ืจืช ื”ืžืฉืชืžืฉ ื“ืจืš ื—ื•ืžืช ืืฉ, ืขืœื™ืš ืœืฆื™ื™ืŸ ืืช ืจืฉืช ื”ืžืฉื ื” 0.0.0.0/0 (ืื™ื•ืจ 17).

ืชื›ื•ื ื•ืช ื”ื”ื’ื“ืจื” ืฉืœ Palo Alto Networks: SSL VPN
ืื™ื•ืจ 17 - ื”ื’ื“ืจืช ืžืื’ืจ ืฉืœ ื›ืชื•ื‘ื•ืช IP ื•ืžืกืœื•ืœื™ื

ืื– ืืชื” ืฆืจื™ืš ืœื”ื’ื“ื™ืจ ืคื•ืจื˜ืœ ืคืจื•ื˜ืงื˜ ื”ืขื•ืœืžื™. ืฆื™ื™ืŸ ืืช ื›ืชื•ื‘ืช ื”-IP ืฉืœ ื—ื•ืžืช ื”ืืฉ, ืคืจื•ืคื™ืœ SSL ะธ ืคืจื•ืคื™ืœ ืื™ืžื•ืช ื•ืจืฉื™ืžืช ื›ืชื•ื‘ื•ืช IP ื—ื™ืฆื•ื ื™ื•ืช ืฉืœ ื—ื•ืžื•ืช ืืฉ ืืœื™ื”ืŸ ื™ืชื—ื‘ืจ ื”ืœืงื•ื—. ืื ื™ืฉ ื›ืžื” ื—ื•ืžื•ืช ืืฉ, ื ื™ืชืŸ ืœื”ื’ื“ื™ืจ ืขื“ื™ืคื•ืช ืœื›ืœ ืื—ืช, ืœืคื™ื” ื”ืžืฉืชืžืฉื™ื ื™ื‘ื—ืจื• ื—ื•ืžืช ืืฉ ืœื”ืชื—ื‘ืจ ืืœื™ื”.

ื‘ืกืขื™ืฃ ืžื›ืฉื™ืจ -> ืœืงื•ื— GlobalProtect ืขืœื™ืš ืœื”ื•ืจื™ื“ ืืช ื”ืคืฆืช ืœืงื•ื— ื”-VPN ืžืฉืจืชื™ Palo Alto Networks ื•ืœื”ืคืขื™ืœ ืื•ืชื”. ื›ื“ื™ ืœื”ืชื—ื‘ืจ, ืขืœ ื”ืžืฉืชืžืฉ ืœื”ื™ื›ื ืก ืœื“ืฃ ื”ืื™ื ื˜ืจื ื˜ ืฉืœ ื”ืคื•ืจื˜ืœ, ืฉื ื”ื•ื ื™ืชื‘ืงืฉ ืœื”ื•ืจื™ื“ ืœืงื•ื— GlobalProtect. ืœืื—ืจ ื”ื”ื•ืจื“ื” ื•ื”ื”ืชืงื ื”, ืชื•ื›ืœ ืœื”ื–ื™ืŸ ืืช ื”ืื™ืฉื•ืจื™ื ืฉืœืš ื•ืœื”ืชื—ื‘ืจ ืœืจืฉืช ื”ืืจื’ื•ื ื™ืช ืฉืœืš ื‘ืืžืฆืขื•ืช SSL VPN.

ืžืกืงื ื”

ื–ื” ืžืฉืœื™ื ืืช ื”ื—ืœืง ืฉืœ Palo Alto Networks ืฉืœ ื”ื”ื’ื“ืจื”. ืื ื• ืžืงื•ื•ื™ื ืฉื”ืžื™ื“ืข ื”ื™ื” ืฉื™ืžื•ืฉื™ ื•ื”ืงื•ืจื ื”ืฉื™ื’ ื”ื‘ื ื” ืฉืœ ื”ื˜ื›ื ื•ืœื•ื’ื™ื•ืช ื”ืžืฉืžืฉื•ืช ื‘-Palo Alto Networks. ืื ื™ืฉ ืœื›ื ืฉืืœื•ืช ืœื’ื‘ื™ ื”ื’ื“ืจื” ื•ื”ืฆืขื•ืช ื‘ื ื•ืฉืื™ื ืœืžืืžืจื™ื ืขืชื™ื“ื™ื™ื, ื›ืชื‘ื• ืื•ืชืŸ ื‘ืชื’ื•ื‘ื•ืช, ื ืฉืžื— ืœืขื ื•ืช.

ืžืงื•ืจ: www.habr.com

ื”ื•ืกืคืช ืชื’ื•ื‘ื”